Working through the IoC, I see these lines
copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe
Why append a random number to a copy of certutil.exe other than to change the file signature?
copy /Y C:\Windows\System32\certutil.exe C:\Windows\cert.exe & echo %RANDOM% >> C:\Windows\cert.exe
Why append a random number to a copy of certutil.exe other than to change the file signature?
Making a copy with a new random name defeats this detection logic.